Site navigation

22% of Phishing Attacks Utilised QR Codes, New Insights Reveal

Thom Carter

,

QR Codes
According to new insights from Hoxhunt, the human risk management platform, the utilisation of QR codes for phishing attacks is on the rise, with the company detecting this approach in 22% of attacks made on its client network during the first weeks of October.

Amid the increase, Hoxhunt incorporated QR codes into its flagship project, the Hoxhunt Challenge, which quantifies human cybersecurity risk and resiliency through simulated attacks across a series of participating organisations in large industries.

The study, which was conducted among a pool of nearly 600,000 employees of varying seniority, found that slightly over one-third (36%) of people successfully identified and reported such an attack. Meanwhile, more than half (59%) didn’t recognise it as a threat, while 5.5% of people scanned the QR code or clicked an accompanying link.

However, the likelihood of successfully identifying and reporting an attack, missing it (i.e. not identifying nor reporting the attack, but also not taking any action that would actively grant attackers access to confidential data), and scanning a QR code or clicking an accompanying link differs by both industry and job function.

Organisations situated in the legal and business services sector successfully identified and reported phishing attacks integrating QR codes 63% of the time, compared to IT’s 44%, and retail’s 18% — the lowest success score of all industries. The retail industry, at 79%, was the industry most likely to miss such a phishing attack.

In terms of job function, legal staff were most likely to successfully identify and report QR code-enabled phishing attacks (78%), while those working in communications were the least likely, at 64%. Communications staff also scanned a QR code or clicked an accompanying phishing link at 1.5% and 3.3% respectively, higher than any other job function in total.


Recommended reading


In light of these findings, the human risk management platform has reiterated the need for continuous employee cybersecurity training, stating that “Failing to provide it promotes a reality of increased risk where organizational data is more of a liability than anything else.”

It also advocates for higher employee engagement as to reduce human risk, and to undergo proper employee onboarding to help mitigate potential risks and vulnerabilities.

QR codes aside, DIGIT last reported on research from Hoxhunt back in March of this year, when the company found that humans are still outperforming generative AI programs when conducting phishing email attacks — at least for now.

Thom Carter

Staff Writer, DIGIT

Latest News

Business Editor's Picks

Movers and Shakers | July 2026

Awards Featured

Just 2 Weeks Left to Enter The Scottish Financial Technology Awards!

AI Cybersecurity

Meta AI Model Hacked Another Company During Cyber Test

Funding

Edinburgh’s Wordsmith Extends Series B With $14m Investment